fix(ext-codec): harden H264/H265 SPS/VPS parsing against malformed input (#4781)

- Add 1MiB cap on parameter set size to prevent memory exhaustion
- Validate SPS/VPS field ranges per H.264/H.265 spec (sps_id, bit_depth, poc_type, ref_frames, etc.)
- Fix Exp-Golomb reader EOF/overflow handling (throw instead of silent zero)
- Use wide integers for crop/delta_scale arithmetic to prevent overflow
- Commit output params only after full parse success (no partial metadata)
- Harden getExtraData with size checks, from_nalu API, AssertFailedException guard
- Avoid redundant update() in inputFrame_l (retry only on SPS change or first-ready)
This commit is contained in:
YuLi
2026-07-22 20:43:21 -07:00
committed by GitHub
parent 7563db36bb
commit daaa74a72e
2 changed files with 330 additions and 73 deletions

View File

@@ -23,6 +23,8 @@
#include <vector>
#include <stdexcept>
#include <climits>
#include <limits>
using namespace std;
using namespace toolkit;
@@ -32,6 +34,10 @@ namespace mediakit {
// ---- 内部比特流工具 ----
namespace {
// SPS 的标准语法规模远小于 1 MiB在复制并去除防竞争字节前设置宽松硬上限避免单个恶意 NALU 触发同等规模的第二次分配。
// Standard SPS syntax is far smaller than 1 MiB; a generous pre-copy cap prevents one hostile NALU from forcing a second allocation of the same scale.
static constexpr size_t kMaxParameterSetSize = 1024 * 1024;
// 去除 RBSP 防竞争字节 (0x00 0x00 0x03 -> 0x00 0x00)
static std::vector<uint8_t> rbsp_from_nalu(const uint8_t *data, size_t size) {
std::vector<uint8_t> out;
@@ -80,9 +86,22 @@ struct BitStream {
uint32_t read_ue() { // Exp-Golomb unsigned
int zeros = 0;
while (!eof() && read_bits(1) == 0) zeros++;
// Exp-Golomb 编码必须包含值为 1 的停止位;此前在停止位前遇到 EOF 会被误判为数值 0并可能驱动后续循环空转。
// Exp-Golomb codes require a one-bit terminator; treating EOF before it as zero could feed bogus counts into later loops.
while (true) {
if (eof()) {
throw std::runtime_error("eof before exp-golomb stop bit");
}
if (read_bits(1) != 0) {
break;
}
// 本读取器返回 uint32_t最多只能接受 31 个前导零32 个前导零需要 33 位编码,且会让后续 se(v) 映射越界。
// This uint32_t reader accepts at most 31 leading zeroes; 32 require a 33-bit code and would overflow later se(v) mapping.
if (++zeros >= 32) {
throw std::runtime_error("exp-golomb overflow");
}
}
if (zeros == 0) return 0;
if (zeros >= 32) throw std::runtime_error("exp-golomb overflow");
return (1u << zeros) - 1 + read_bits(zeros);
}
@@ -90,24 +109,35 @@ struct BitStream {
uint32_t v = read_ue();
return (v & 1) ? (int32_t)((v + 1) >> 1) : -(int32_t)(v >> 1);
}
};
} // anonymous namespace
// ---- H264 SPS 解析 ----
static bool getAVCInfo(const char *sps_raw, size_t sps_len, int &iVideoWidth, int &iVideoHeight, float &iVideoFps) {
if (sps_len < 4) return false;
// sps_raw[0] 是 NAL header从第 1 字节开始是 RBSP
auto rbsp = rbsp_from_nalu((const uint8_t *)sps_raw + 1, sps_len - 1);
if (rbsp.size() < 3) return false;
if (sps_len < 4 || sps_len > kMaxParameterSetSize) return false;
try {
// RBSP 分配也可能因恶意超大 NALU 抛出异常;将其纳入保护范围,才能维持本接口只返回 false 的失败语义。
// RBSP allocation can throw for a maliciously large NALU; keep it inside the guard so this boolean API fails with false.
// sps_raw[0] 是 NAL header从第 1 字节开始是 RBSP
auto rbsp = rbsp_from_nalu((const uint8_t *)sps_raw + 1, sps_len - 1);
if (rbsp.size() < 3) return false;
BitStream bs(rbsp.data(), rbsp.size());
int parsed_width = 0;
int parsed_height = 0;
float parsed_fps = 0.0f;
uint8_t profile_idc = (uint8_t)bs.read_bits(8); // profile_idc
bs.skip_bits(8); // constraint flags + reserved
bs.skip_bits(8); // level_idc
bs.read_ue(); // seq_parameter_set_id
uint32_t seq_parameter_set_id = bs.read_ue();
// H.264 只定义 0..31 的 SPS id拒绝相邻越界值避免接受无法由标准参数集表表示的配置。
// H.264 defines SPS ids only in 0..31; reject the adjacent out-of-range value instead of accepting an unrepresentable parameter set.
if (seq_parameter_set_id > 31) {
return false;
}
uint32_t chroma_format_idc = 1;
if (profile_idc == 100 || profile_idc == 110 || profile_idc == 122 ||
@@ -118,8 +148,13 @@ static bool getAVCInfo(const char *sps_raw, size_t sps_len, int &iVideoWidth, in
return false;
}
if (chroma_format_idc == 3) bs.skip_bits(1); // separate_colour_plane_flag
bs.read_ue(); // bit_depth_luma_minus8
bs.read_ue(); // bit_depth_chroma_minus8
uint32_t bit_depth_luma_minus8 = bs.read_ue();
uint32_t bit_depth_chroma_minus8 = bs.read_ue();
// 两个位深字段分别受 0..6 限制,但语法允许它们取不同值;强制相等会拒绝可以安全提取尺寸的合法 SPS。
// Each bit-depth offset is independently limited to 0..6, while the syntax permits different values; requiring equality rejects valid SPS whose dimensions are still safe to extract.
if (bit_depth_luma_minus8 > 6 || bit_depth_chroma_minus8 > 6) {
return false;
}
bs.skip_bits(1); // qpprime_y_zero_transform_bypass_flag
if (bs.read_bits(1)) { // seq_scaling_matrix_present_flag
int cnt = (chroma_format_idc != 3) ? 8 : 12;
@@ -128,7 +163,15 @@ static bool getAVCInfo(const char *sps_raw, size_t sps_len, int &iVideoWidth, in
int sz = (i < 6) ? 16 : 64;
int last = 8, next = 8;
for (int j = 0; j < sz; j++) {
if (next != 0) next = (last + bs.read_se() + 256) % 256;
if (next != 0) {
// delta_scale 来自不可信位流,直接用 int 相加可能触发有符号溢出;宽类型和规范化取模可保持标准语义。
// delta_scale is untrusted and may overflow int addition; wide arithmetic plus normalized modulo preserves the SPS rule.
int64_t value = (int64_t)last + bs.read_se() + 256;
next = (int)(value % 256);
if (next < 0) {
next += 256;
}
}
last = (next == 0) ? last : next;
}
}
@@ -136,18 +179,42 @@ static bool getAVCInfo(const char *sps_raw, size_t sps_len, int &iVideoWidth, in
}
}
bs.read_ue(); // log2_max_frame_num_minus4
uint32_t log2_max_frame_num_minus4 = bs.read_ue();
// 规范范围为 0..12;即使当前只提取宽高,也不能把越界 SPS 当作有效配置发布。
// The specified range is 0..12; even a dimensions-only parser must not publish an out-of-range SPS as valid configuration.
if (log2_max_frame_num_minus4 > 12) {
return false;
}
uint32_t pic_order_cnt_type = bs.read_ue();
if (pic_order_cnt_type == 0) {
bs.read_ue(); // log2_max_pic_order_cnt_lsb_minus4
uint32_t log2_max_pic_order_cnt_lsb_minus4 = bs.read_ue();
// POC LSB 位数增量同样仅允许 0..12,越界值会描述标准外的帧序号空间。
// The POC-LSB bit-count offset is likewise limited to 0..12; larger values describe a non-standard picture-order space.
if (log2_max_pic_order_cnt_lsb_minus4 > 12) {
return false;
}
} else if (pic_order_cnt_type == 1) {
bs.skip_bits(1); // delta_pic_order_always_zero_flag
bs.read_se(); // offset_for_non_ref_pic
bs.read_se(); // offset_for_top_to_bottom_field
uint32_t n = bs.read_ue();
// 标准只允许最多 255 个 offset先校验再循环避免恶意计数长时间占用媒体输入线程。
// The standard allows at most 255 offsets; validate before looping so a hostile count cannot monopolize the media input thread.
if (n > 255) {
return false;
}
for (uint32_t i = 0; i < n; i++) bs.read_se();
} else if (pic_order_cnt_type != 2) {
// 仅 0、1、2 是有效 POC 类型;继续解析未知类型会使后续字段错位并可能接受伪造尺寸。
// Only POC types 0, 1, and 2 are valid; continuing with another value misaligns later fields and may accept forged dimensions.
return false;
}
uint32_t max_num_ref_frames = bs.read_ue();
// H.264 解码图像缓冲区最多表示 16 个参考帧;提前拒绝 17 可保持与原解析器的标准边界一致。
// The H.264 decoded-picture buffer represents at most 16 reference frames; rejecting 17 preserves the prior parser's standard boundary.
if (max_num_ref_frames > 16) {
return false;
}
bs.read_ue(); // max_num_ref_frames
bs.skip_bits(1); // gaps_in_frame_num_value_allowed_flag
uint32_t pic_width_in_mbs_minus1 = bs.read_ue();
@@ -174,15 +241,23 @@ static bool getAVCInfo(const char *sps_raw, size_t sps_len, int &iVideoWidth, in
crop_unit_y = 2 - frame_mbs_only_flag;
}
uint64_t raw_width = (uint64_t)(pic_width_in_mbs_minus1 + 1) * 16;
uint64_t raw_height = (uint64_t)(pic_height_in_map_units_minus1 + 1) * 16 * (2 - frame_mbs_only_flag);
// 宏块计数来自不可信 ue(v),必须在加一前提升到 64 位否则未来若放宽读取上限uint32_t 加法可能先回绕为零。
// Macroblock counts are untrusted ue(v) values and must be widened before adding one; otherwise a future reader extension could wrap uint32_t to zero first.
uint64_t raw_width = ((uint64_t)pic_width_in_mbs_minus1 + 1) * 16;
uint64_t raw_height = ((uint64_t)pic_height_in_map_units_minus1 + 1) * 16 * (2 - frame_mbs_only_flag);
uint64_t crop_w = ((uint64_t)crop_left + crop_right) * crop_unit_x;
uint64_t crop_h = ((uint64_t)crop_top + crop_bottom) * crop_unit_y;
if (crop_w >= raw_width || crop_h >= raw_height) return false;
iVideoWidth = (int)(raw_width - crop_w);
iVideoHeight = (int)(raw_height - crop_h);
uint64_t display_width = raw_width - crop_w;
uint64_t display_height = raw_height - crop_h;
// 输出接口使用 int转换前限制范围避免恶意尺寸触发实现定义的窄化并污染下游元数据。
// The output API uses int; range-check before narrowing so hostile dimensions cannot produce implementation-defined metadata.
if (display_width > INT_MAX || display_height > INT_MAX) {
return false;
}
parsed_width = (int)display_width;
parsed_height = (int)display_height;
iVideoFps = 0.0f;
if (bs.read_bits(1)) { // vui_parameters_present_flag
if (bs.read_bits(1)) { // aspect_ratio_info_present_flag
uint32_t ar = bs.read_bits(8);
@@ -201,13 +276,23 @@ static bool getAVCInfo(const char *sps_raw, size_t sps_len, int &iVideoWidth, in
uint32_t time_scale = bs.read_bits(32);
bs.skip_bits(1); // fixed_frame_rate_flag
if (num_units_in_tick > 0) {
iVideoFps = (float)time_scale / (2.0f * (float)num_units_in_tick);
parsed_fps = (float)time_scale / (2.0f * (float)num_units_in_tick);
}
}
}
return iVideoWidth > 0 && iVideoHeight > 0;
if (parsed_width <= 0 || parsed_height <= 0) {
return false;
}
// 本接口只提取宽高和 VUI 时序HRD 及其后的尾部语法不影响这些结果,也不应把元数据提取器扩展成完整合规验证器。
// This API only extracts dimensions and VUI timing; HRD and later tail syntax do not affect them and must not turn this metadata reader into a full conformance validator.
// 已消费字段全部成功后再写回,既保留项目原有的宽松尾部兼容性,也避免异常发布部分结果。
// Commit only after every consumed field succeeds, preserving the project's permissive tail compatibility without publishing partial results on failure.
iVideoWidth = parsed_width;
iVideoHeight = parsed_height;
iVideoFps = parsed_fps;
return true;
} catch (...) {
return iVideoWidth > 0 && iVideoHeight > 0;
return false;
}
}
@@ -340,19 +425,47 @@ toolkit::Buffer::Ptr H264Track::getExtraData() const {
#ifdef ENABLE_MP4
struct mpeg4_avc_t avc;
memset(&avc, 0, sizeof(avc));
string sps_pps = string("\x00\x00\x00\x01", 4) + _sps + string("\x00\x00\x00\x01", 4) + _pps;
h264_annexbtomp4(&avc, sps_pps.data(), (int)sps_pps.size(), NULL, 0, NULL, NULL);
std::string extra_data;
extra_data.resize(1024);
auto extra_data_size = mpeg4_avc_decoder_configuration_record_save(&avc, (uint8_t *)extra_data.data(), extra_data.size());
if (extra_data_size == -1) {
WarnL << "生成H264 extra_data 失败";
// mpeg4_avc_t 使用固定数组保存 SPS/PPS第三方转换器在总长度超限时会触发断言这里用减法检查避免加法溢出并在进入转换器前正常失败。
// mpeg4_avc_t stores SPS/PPS in a fixed array and its converter asserts when their total size exceeds it; subtraction-based checks avoid addition overflow and fail cleanly first.
if (_sps.size() > sizeof(avc.data) || _pps.size() > sizeof(avc.data) - _sps.size()) {
WarnL << "H264参数集过大无法生成extra_data: sps=" << _sps.size() << ", pps=" << _pps.size()
<< ", capacity=" << sizeof(avc.data);
return nullptr;
}
// 第三方转换器用项目 assert 宏报告参数集语法错误,该宏会抛出 AssertFailedException仅检查长度无法覆盖内容截断的 Exp-Golomb 编码,因此只在 Track 边界收口第三方调用并维持返回 nullptr 的失败语义,其他异常仍正常传播。
// The third-party converter reports parameter-set syntax errors through the project assert macro, which throws AssertFailedException; length checks cannot cover truncated Exp-Golomb content, so only third-party calls are contained at the Track boundary to preserve the nullptr failure contract while other exceptions still propagate.
try {
string sps_pps = string("\x00\x00\x00\x01", 4) + _sps + string("\x00\x00\x00\x01", 4) + _pps;
// annexbtomp4 在仅填充配置、没有媒体输出缓冲区时固定返回 0from_nalu 是库为该场景提供的封装,并会确认 SPS/PPS 已写入 avc。
// annexbtomp4 always returns zero when only populating configuration without a media output buffer; from_nalu wraps that use case and verifies SPS/PPS were stored in avc.
if (mpeg4_avc_from_nalu((const uint8_t *)sps_pps.data(), sps_pps.size(), &avc) <= 0) {
WarnL << "生成H264 extra_data时转换参数集失败";
return nullptr;
}
// 固定的 1024 字节缓冲区小于 mpeg4_avc_t 可保存的参数集;按输入大小分配,并为 AVC 配置记录字段保留充足空间。
// A fixed 1024-byte buffer is smaller than the parameter sets held by mpeg4_avc_t; size it from the input and leave ample room for AVC record fields.
std::string extra_data;
extra_data.resize(sps_pps.size() + 64);
auto extra_data_size = mpeg4_avc_decoder_configuration_record_save(&avc, (uint8_t *)&extra_data[0], extra_data.size());
if (extra_data_size <= 0) {
WarnL << "生成H264 extra_data 失败";
return nullptr;
}
extra_data.resize(extra_data_size);
return std::make_shared<BufferString>(std::move(extra_data));
} catch (const AssertFailedException &ex) {
WarnL << "生成H264 extra_data时参数集无效: " << ex.what();
return nullptr;
}
extra_data.resize(extra_data_size);
return std::make_shared<BufferString>(std::move(extra_data));
#else
// AVCDecoderConfigurationRecord 使用 16 位字段保存单个 SPS/PPS 长度;拒绝截断转换,同时保证下方读取 profile/level 字节安全。
// AVCDecoderConfigurationRecord uses 16-bit SPS/PPS lengths; reject narrowing conversions and ensure the profile/level bytes read below are present.
if (_sps.size() < 4 || _sps.size() > std::numeric_limits<uint16_t>::max() ||
_pps.size() > std::numeric_limits<uint16_t>::max()) {
WarnL << "H264参数集长度无效无法生成extra_data: sps=" << _sps.size() << ", pps=" << _pps.size();
return nullptr;
}
std::string extra_data;
// AVCDecoderConfigurationRecord start
extra_data.push_back(1); // version
@@ -431,6 +544,7 @@ bool H264Track::inputFrame_l(const Frame::Ptr &frame) {
// AUD帧丢弃
return false;
}
bool was_ready = ready();
bool ret = true;
switch (type) {
case H264Frame::NAL_SPS: {
@@ -466,7 +580,10 @@ bool H264Track::inputFrame_l(const Frame::Ptr &frame) {
break;
}
if (_width == 0 && ready()) {
// 仅当 SPS 改变或本帧首次补齐配置时重试PPS 不包含宽高,配置已齐全后重复 PPS 只会反复解析同一份失败 SPS。
// Retry only when the SPS changes or this frame first completes configuration: PPS carries no dimensions, so repeated PPS after readiness would only reparse the same failed SPS.
bool configuration_became_ready = !was_ready && ready();
if (_width == 0 && ready() && (type == H264Frame::NAL_SPS || configuration_became_ready)) {
update();
}
return ret;

View File

@@ -17,6 +17,7 @@
#include <vector>
#include <stdexcept>
#include <climits>
#ifdef ENABLE_MP4
#include "mpeg4-hevc.h"
@@ -30,6 +31,10 @@ namespace mediakit {
// ---- 内部比特流工具H265 ----
namespace {
// VPS/SPS 的实际语法规模远小于 1 MiB在复制 RBSP 前设置宽松上限,防止恶意参数集制造同等规模的额外分配。
// Practical VPS/SPS syntax is far smaller than 1 MiB; a generous pre-copy cap prevents hostile parameter sets from forcing an equal-sized allocation.
static constexpr size_t kMaxParameterSetSize = 1024 * 1024;
static std::vector<uint8_t> h265_rbsp_from_nalu(const uint8_t *data, size_t size) {
std::vector<uint8_t> out;
out.reserve(size);
@@ -71,15 +76,29 @@ struct H265BS {
}
uint32_t read_ue() {
int z = 0;
while (!eof() && read_bits(1) == 0) z++;
// Exp-Golomb 编码必须包含值为 1 的停止位;此前在停止位前遇到 EOF 会被误判为 0并掩盖 SPS 截断。
// Exp-Golomb codes require a one-bit terminator; treating EOF before it as zero concealed truncated SPS data.
while (true) {
if (eof()) {
throw std::runtime_error("eof before exp-golomb stop bit");
}
if (read_bits(1) != 0) {
break;
}
// 本读取器返回 uint32_t最多只能接受 31 个前导零32 个前导零属于无法表示的 33 位 ue(v) 编码。
// This uint32_t reader accepts at most 31 leading zeroes; 32 form a 33-bit ue(v) code that cannot be represented here.
if (++z >= 32) {
throw std::runtime_error("exp-golomb overflow");
}
}
if (z == 0) return 0;
if (z >= 32) throw std::runtime_error("exp-golomb overflow");
return (1u << z) - 1 + read_bits(z);
}
int32_t read_se() {
uint32_t v = read_ue();
return (v & 1) ? (int32_t)((v + 1) >> 1) : -(int32_t)(v >> 1);
}
// profile_tier_level(profilePresentFlag, maxNumSubLayersMinus1)
void skip_profile_tier_level(bool profilePresentFlag, uint32_t maxNumSubLayersMinus1) {
if (profilePresentFlag) {
@@ -112,15 +131,23 @@ struct H265BS {
// ---- H265 VPS 解析(只提取帧率用的 timing info ----
static bool parse_hevc_vps_fps(const uint8_t *data, size_t size, float &fps) {
// data 为 NALU 原始数据(含 NAL header
if (size < 3) return false;
auto rbsp = h265_rbsp_from_nalu(data, size);
if (size < 3 || size > kMaxParameterSetSize) return false;
try {
// RBSP 分配必须处于异常保护内,避免超大恶意 VPS 让 bad_alloc 逃出布尔解析接口。
// Keep RBSP allocation inside the guard so a huge hostile VPS cannot leak bad_alloc through the boolean parser API.
auto rbsp = h265_rbsp_from_nalu(data, size);
H265BS bs(rbsp.data(), rbsp.size());
float parsed_fps = fps;
// NALU header: forbidden_zero_bit(1) + nal_unit_type(6) + nuh_layer_id(6) + nuh_temporal_id_plus1(3)
bs.skip_bits(16);
// vps_video_parameter_set_id(4) + vps_reserved_three_2bits(2) + vps_max_layers_minus1(6)
bs.skip_bits(4 + 2 + 6);
uint32_t vps_max_sub_layers_minus1 = bs.read_bits(3);
// HEVC 最多定义 7 个时间子层,因此 minus1 字段只允许 0..6;值 7 为保留值,不能继续控制后续循环。
// HEVC defines at most seven temporal sub-layers, so the minus-one field is limited to 0..6; reserved value 7 must not control later loops.
if (vps_max_sub_layers_minus1 > 6) {
return false;
}
bs.skip_bits(1); // vps_temporal_id_nesting_flag
bs.skip_bits(16); // vps_reserved_0xffff_16bits
bs.skip_profile_tier_level(true, vps_max_sub_layers_minus1);
@@ -132,7 +159,15 @@ static bool parse_hevc_vps_fps(const uint8_t *data, size_t size, float &fps) {
bs.read_ue(); // vps_max_latency_increase_plus1
}
uint32_t vps_max_layer_id = bs.read_bits(6);
// 63 虽为当前规范的保留值,但规范要求解码端允许它出现在语法中;这里至多跳过 64 个 layer flag且下方会预检实际位数不能因此丢弃 VPS 时序。
// Although 63 is reserved by the current specification, decoders must allow it in the syntax; at most 64 layer flags are skipped here and their bits are preflighted below, so VPS timing must not be discarded for this value.
uint32_t vps_num_layer_sets_minus1 = bs.read_ue();
// 标准上限为 1023并且每个 layer flag 都必须实际存在;本元数据解析器只做有界跳过,不扩展为检查 layer set 非空、唯一性的完整解码一致性校验。
// The standard limit is 1023 and every layer flag must be present; this metadata parser only performs bounded skipping and intentionally does not grow into full decoder-conformance checks for non-empty, unique layer sets.
uint64_t layer_flag_count = (uint64_t)vps_num_layer_sets_minus1 * (vps_max_layer_id + 1);
if (vps_num_layer_sets_minus1 > 1023 || layer_flag_count > bs.bits_left()) {
return false;
}
for (uint32_t i = 1; i <= vps_num_layer_sets_minus1; i++) {
for (uint32_t j = 0; j <= vps_max_layer_id; j++) bs.skip_bits(1);
}
@@ -140,9 +175,12 @@ static bool parse_hevc_vps_fps(const uint8_t *data, size_t size, float &fps) {
uint32_t vps_num_units_in_tick = bs.read_bits(32);
uint32_t vps_time_scale = bs.read_bits(32);
if (vps_num_units_in_tick > 0) {
fps = (float)vps_time_scale / (float)vps_num_units_in_tick;
parsed_fps = (float)vps_time_scale / (float)vps_num_units_in_tick;
}
}
// 本函数只读取 VPS 中到 timing_info 为止的字段;后续 HRD/扩展不影响帧率,继续解析只会扩大本元数据接口的职责和风险面。
// This function only consumes VPS fields through timing_info; later HRD/extensions do not affect frame rate, and parsing them would only broaden this metadata API's responsibility and risk surface.
fps = parsed_fps;
return true;
} catch (...) {
return false;
@@ -152,16 +190,31 @@ static bool parse_hevc_vps_fps(const uint8_t *data, size_t size, float &fps) {
// ---- H265 SPS 解析(宽高 + 备用帧率) ----
static bool parse_hevc_sps(const uint8_t *data, size_t size,
int &width, int &height, float &fps) {
if (size < 3) return false;
auto rbsp = h265_rbsp_from_nalu(data, size);
if (size < 3 || size > kMaxParameterSetSize) return false;
try {
// RBSP 分配也属于解析失败路径;纳入异常保护才能保证 malformed input 统一返回 false。
// RBSP allocation is part of parsing failure; guard it so malformed input consistently returns false.
auto rbsp = h265_rbsp_from_nalu(data, size);
H265BS bs(rbsp.data(), rbsp.size());
int parsed_width = 0;
int parsed_height = 0;
float parsed_fps = fps;
bs.skip_bits(16); // NALU header
bs.skip_bits(4); // sps_video_parameter_set_id
uint32_t sps_max_sub_layers_minus1 = bs.read_bits(3);
// 与 VPS 相同SPS 的时间子层 minus1 字段只允许 0..6;先拒绝保留值 7避免错误位移和循环次数。
// As in the VPS, the SPS temporal-sub-layer minus-one field is limited to 0..6; reject reserved 7 before it skews offsets and loop counts.
if (sps_max_sub_layers_minus1 > 6) {
return false;
}
bs.skip_bits(1); // sps_temporal_id_nesting_flag
bs.skip_profile_tier_level(true, sps_max_sub_layers_minus1);
bs.read_ue(); // sps_seq_parameter_set_id
uint32_t sps_seq_parameter_set_id = bs.read_ue();
// HEVC SPS id 的标准范围为 0..15;拒绝 16避免接受参数集表无法索引的配置。
// HEVC SPS ids are defined in 0..15; reject 16 instead of accepting configuration that the parameter-set table cannot index.
if (sps_seq_parameter_set_id > 15) {
return false;
}
uint32_t chroma_format_idc = bs.read_ue();
if (chroma_format_idc > 3) {
return false;
@@ -173,31 +226,56 @@ static bool parse_hevc_sps(const uint8_t *data, size_t size,
if (bs.read_bits(1)) { // conformance_window_flag
uint32_t sub_width_c = (chroma_format_idc == 1 || chroma_format_idc == 2) ? 2 : 1;
uint32_t sub_height_c = (chroma_format_idc == 1) ? 2 : 1;
uint32_t crop_left = bs.read_ue() * sub_width_c;
uint32_t crop_right = bs.read_ue() * sub_width_c;
uint32_t crop_top = bs.read_ue() * sub_height_c;
uint32_t crop_bottom = bs.read_ue() * sub_height_c;
if (crop_left + crop_right > pic_width || crop_top + crop_bottom > pic_height) {
// crop offset 由不可信 UE 值控制;使用 uint64_t 完成乘加,避免 uint32_t 回绕后绕过边界检查。
// Crop offsets come from untrusted UE values; wide multiplication and addition prevent uint32_t wraparound from bypassing bounds checks.
uint64_t crop_left = (uint64_t)bs.read_ue() * sub_width_c;
uint64_t crop_right = (uint64_t)bs.read_ue() * sub_width_c;
uint64_t crop_top = (uint64_t)bs.read_ue() * sub_height_c;
uint64_t crop_bottom = (uint64_t)bs.read_ue() * sub_height_c;
uint64_t crop_width = crop_left + crop_right;
uint64_t crop_height = crop_top + crop_bottom;
if (crop_width >= pic_width || crop_height >= pic_height) {
return false;
}
pic_width -= crop_left + crop_right;
pic_height -= crop_top + crop_bottom;
pic_width -= (uint32_t)crop_width;
pic_height -= (uint32_t)crop_height;
}
width = (int)pic_width;
height = (int)pic_height;
// 输出接口使用 int转换前检查范围避免超大尺寸产生实现定义的窄化结果。
// The output API uses int; range-check before narrowing to avoid implementation-defined results for oversized dimensions.
if (pic_width == 0 || pic_height == 0 || pic_width > INT_MAX || pic_height > INT_MAX) {
return false;
}
parsed_width = (int)pic_width;
parsed_height = (int)pic_height;
bs.read_ue(); // bit_depth_luma_minus8
bs.read_ue(); // bit_depth_chroma_minus8
uint32_t bit_depth_luma_minus8 = bs.read_ue();
uint32_t bit_depth_chroma_minus8 = bs.read_ue();
// HEVC 分别定义亮度和色度位深增量,两者各自限制为 0..8 但不要求相等;独立校验可避免接受标准范围外的配置。
// HEVC defines separate luma and chroma bit-depth offsets, each limited to 0..8 without an equality requirement; validate both independently to reject out-of-range configuration.
if (bit_depth_luma_minus8 > 8 || bit_depth_chroma_minus8 > 8) {
return false;
}
uint32_t log2_max_pic_order_cnt_lsb_minus4 = bs.read_ue();
// 该值标准范围为 0..12;限制后续 skip_bits 参数可表示且不会被恶意值扭曲。
// Its standard range is 0..12; enforcing it keeps later skip_bits counts representable and input-safe.
if (log2_max_pic_order_cnt_lsb_minus4 > 12) {
return false;
}
bool sps_sub_layer_ordering_info_present_flag = bs.read_bits(1) != 0;
uint32_t start = sps_sub_layer_ordering_info_present_flag ? 0 : sps_max_sub_layers_minus1;
for (uint32_t i = start; i <= sps_max_sub_layers_minus1; i++) {
bs.read_ue(); bs.read_ue(); bs.read_ue();
}
bs.read_ue(); // log2_min_luma_coding_block_size_minus3
bs.read_ue(); // log2_diff_max_min_luma_coding_block_size
uint32_t log2_min_luma_coding_block_size_minus3 = bs.read_ue();
uint32_t log2_diff_max_min_luma_coding_block_size = bs.read_ue();
// 两个编码块尺寸字段各自仅允许 0..3;即使本接口只跳过后续字段,也不能把越界参数集当作有效元数据来源。
// Both coding-block-size fields are limited to 0..3; even when later fields are only traversed, an out-of-range parameter set is not a valid metadata source.
if (log2_min_luma_coding_block_size_minus3 > 3 ||
log2_diff_max_min_luma_coding_block_size > 3) {
return false;
}
bs.read_ue(); // log2_min_luma_transform_block_size_minus2
bs.read_ue(); // log2_diff_max_min_luma_transform_block_size
bs.read_ue(); // max_transform_hierarchy_depth_inter
@@ -227,6 +305,11 @@ static bool parse_hevc_sps(const uint8_t *data, size_t size,
}
uint32_t num_short_term_ref_pic_sets = bs.read_ue();
// 标准最多允许 64 个短期 RPS循环前拒绝超限值避免参数集放大媒体线程工作量。
// The standard permits at most 64 short-term RPS entries; reject larger counts before they amplify media-thread work.
if (num_short_term_ref_pic_sets > 64) {
return false;
}
uint32_t prev_num_delta_pocs = 0;
for (uint32_t i = 0; i < num_short_term_ref_pic_sets; i++) {
bool inter_ref = (i != 0) && bs.read_bits(1) != 0;
@@ -240,10 +323,20 @@ static bool parse_hevc_sps(const uint8_t *data, size_t size,
bool use = !used && bs.read_bits(1) != 0;
if (used || use) cnt++;
}
// 单个 RPS 最多容纳 32 个 delta POC限制派生计数防止后续循环被恶意状态持续放大。
// A single RPS holds at most 32 delta POCs; cap the derived count before it controls the next input-driven loop.
if (cnt > 32) {
return false;
}
prev_num_delta_pocs = cnt;
} else {
uint32_t num_neg = bs.read_ue();
uint32_t num_pos = bs.read_ue();
// 规范派生的每类参考图像全局上限小于 16这里只约束输入驱动循环和加法不扩展为校验其与各时间子层 DPB 字段的完整解码一致性。
// The derived global limit for each reference class is below 16; this check only bounds input-driven loops and addition, without growing into full decoder-conformance validation against every temporal sub-layer's DPB fields.
if (num_neg >= 16 || num_pos >= 16) {
return false;
}
prev_num_delta_pocs = num_neg + num_pos;
for (uint32_t j = 0; j < num_neg; j++) { bs.read_ue(); bs.skip_bits(1); }
for (uint32_t j = 0; j < num_pos; j++) { bs.read_ue(); bs.skip_bits(1); }
@@ -252,6 +345,11 @@ static bool parse_hevc_sps(const uint8_t *data, size_t size,
if (bs.read_bits(1)) { // long_term_ref_pics_present_flag
uint32_t n = bs.read_ue();
// 标准最多允许 32 个长期参考图像;在循环前校验,避免恶意计数阻塞输入线程。
// The standard permits at most 32 long-term references; validate before looping to keep hostile counts off the input thread.
if (n > 32) {
return false;
}
uint32_t log2_max = log2_max_pic_order_cnt_lsb_minus4 + 4;
for (uint32_t i = 0; i < n; i++) {
bs.skip_bits(log2_max); // lt_ref_pic_poc_lsb_sps
@@ -281,29 +379,46 @@ static bool parse_hevc_sps(const uint8_t *data, size_t size,
if (bs.read_bits(1)) { // vui_timing_info_present_flag
uint32_t num_units = bs.read_bits(32);
uint32_t time_scale = bs.read_bits(32);
if (num_units > 0 && fps <= 0.0f) {
fps = (float)time_scale / (float)num_units;
if (num_units > 0 && parsed_fps <= 0.0f) {
parsed_fps = (float)time_scale / (float)num_units;
}
}
}
return width > 0 && height > 0;
// 本接口只提取宽高和 VUI 时序;其后的 HRD、bitstream restriction、SPS 扩展及 RBSP 尾部均不影响这些结果。
// This API only extracts dimensions and VUI timing; later HRD, bitstream restrictions, SPS extensions, and the RBSP tail do not affect those results.
// 已消费字段全部成功后再提交,既维持原有扩展码流兼容性,也避免异常发布部分元数据。
// Commit only after every consumed field succeeds, preserving existing extension-stream compatibility without publishing partial metadata on failure.
width = parsed_width;
height = parsed_height;
fps = parsed_fps;
return true;
} catch (...) {
return width > 0 && height > 0;
return false;
}
}
bool getHEVCInfo(const char *vps, size_t vps_len, const char *sps, size_t sps_len,
int &iVideoWidth, int &iVideoHeight, float &iVideoFps) {
iVideoWidth = 0; iVideoHeight = 0; iVideoFps = 0.0f;
int parsed_width = 0;
int parsed_height = 0;
float parsed_fps = 0.0f;
// 先从 VPS 提取帧率
if (vps_len > 2) {
parse_hevc_vps_fps((const uint8_t *)vps, vps_len, iVideoFps);
parse_hevc_vps_fps((const uint8_t *)vps, vps_len, parsed_fps);
}
// 再从 SPS 提取宽高(如果 VPS 没有帧率SPS VUI 里也可能有)
if (sps_len <= 2) return false;
return parse_hevc_sps((const uint8_t *)sps, sps_len, iVideoWidth, iVideoHeight, iVideoFps);
if (!parse_hevc_sps((const uint8_t *)sps, sps_len, parsed_width, parsed_height, parsed_fps)) {
return false;
}
// 对外参数只在 VPS/SPS 解析成功后再依次发布,确保失败不会清空或污染调用方已有元数据;这不是跨线程原子更新。
// Publish public outputs only after VPS/SPS parsing succeeds so failure preserves caller metadata; these assignments are not cross-thread atomic.
iVideoWidth = parsed_width;
iVideoHeight = parsed_height;
iVideoFps = parsed_fps;
return true;
}
bool getHEVCInfo(const string &strVps, const string &strSps, int &iVideoWidth, int &iVideoHeight, float &iVideoFps) {
@@ -357,6 +472,7 @@ bool H265Track::inputFrame(const Frame::Ptr &frame) {
bool H265Track::inputFrame_l(const Frame::Ptr &frame) {
int type = H265_TYPE(frame->data()[frame->prefixSize()]);
bool was_ready = ready();
bool ret = true;
switch (type) {
case H265Frame::NAL_VPS: {
@@ -389,7 +505,10 @@ bool H265Track::inputFrame_l(const Frame::Ptr &frame) {
break;
}
}
if (_width == 0 && ready()) {
// 仅当 SPS 改变或本帧首次补齐配置时重试:宽高解析失败后,重复 VPS/PPS 无法改变 SPS 结果,只会在媒体线程重复做无效工作。
// Retry only when the SPS changes or this frame first completes configuration: after dimension parsing fails, repeated VPS/PPS cannot change the SPS result and only repeat work on the media thread.
bool configuration_became_ready = !was_ready && ready();
if (_width == 0 && ready() && (type == H265Frame::NAL_SPS || configuration_became_ready)) {
update();
}
return ret;
@@ -400,18 +519,40 @@ toolkit::Buffer::Ptr H265Track::getExtraData() const {
#ifdef ENABLE_MP4
struct mpeg4_hevc_t hevc;
memset(&hevc, 0, sizeof(hevc));
string vps_sps_pps = string("\x00\x00\x00\x01", 4) + _vps + string("\x00\x00\x00\x01", 4) + _sps + string("\x00\x00\x00\x01", 4) + _pps;
h265_annexbtomp4(&hevc, vps_sps_pps.data(), (int) vps_sps_pps.size(), NULL, 0, NULL, NULL);
std::string extra_data;
extra_data.resize(1024);
auto extra_data_size = mpeg4_hevc_decoder_configuration_record_save(&hevc, (uint8_t *)extra_data.data(), extra_data.size());
if (extra_data_size == -1) {
WarnL << "生成H265 extra_data 失败";
// mpeg4_hevc_t 使用固定数组保存 VPS/SPS/PPS第三方转换器在总长度超限时会触发断言逐项减法检查既避免加法溢出也把失败限制在本 Track 内。
// mpeg4_hevc_t stores VPS/SPS/PPS in a fixed array and its converter asserts when their total size exceeds it; staged subtraction avoids overflow and keeps failure in this Track.
if (_vps.size() > sizeof(hevc.data) || _sps.size() > sizeof(hevc.data) - _vps.size() ||
_pps.size() > sizeof(hevc.data) - _vps.size() - _sps.size()) {
WarnL << "H265参数集过大无法生成extra_data: vps=" << _vps.size() << ", sps=" << _sps.size()
<< ", pps=" << _pps.size() << ", capacity=" << sizeof(hevc.data);
return nullptr;
}
// 第三方转换器用项目 assert 宏报告参数集语法错误,该宏会抛出 AssertFailedException仅检查长度无法覆盖内容截断的 Exp-Golomb 编码,因此只在 Track 边界收口第三方调用并维持返回 nullptr 的失败语义,其他异常仍正常传播。
// The third-party converter reports parameter-set syntax errors through the project assert macro, which throws AssertFailedException; length checks cannot cover truncated Exp-Golomb content, so only third-party calls are contained at the Track boundary to preserve the nullptr failure contract while other exceptions still propagate.
try {
string vps_sps_pps = string("\x00\x00\x00\x01", 4) + _vps + string("\x00\x00\x00\x01", 4) + _sps + string("\x00\x00\x00\x01", 4) + _pps;
// annexbtomp4 在仅填充配置、没有媒体输出缓冲区时固定返回 0from_nalu 是库为该场景提供的封装,并会确认参数集已写入 hevc。
// annexbtomp4 always returns zero when only populating configuration without a media output buffer; from_nalu wraps that use case and verifies parameter sets were stored in hevc.
if (mpeg4_hevc_from_nalu((const uint8_t *)vps_sps_pps.data(), vps_sps_pps.size(), &hevc) <= 0) {
WarnL << "生成H265 extra_data时转换参数集失败";
return nullptr;
}
// 固定的 1024 字节缓冲区小于 mpeg4_hevc_t 可保存的参数集;按输入大小分配,并为 HEVC 配置记录字段保留充足空间。
// A fixed 1024-byte buffer is smaller than the parameter sets held by mpeg4_hevc_t; size it from the input and leave ample room for HEVC record fields.
std::string extra_data;
extra_data.resize(vps_sps_pps.size() + 64);
auto extra_data_size = mpeg4_hevc_decoder_configuration_record_save(&hevc, (uint8_t *)&extra_data[0], extra_data.size());
if (extra_data_size <= 0) {
WarnL << "生成H265 extra_data 失败";
return nullptr;
}
extra_data.resize(extra_data_size);
return std::make_shared<BufferString>(std::move(extra_data));
} catch (const AssertFailedException &ex) {
WarnL << "生成H265 extra_data时参数集无效: " << ex.what();
return nullptr;
}
extra_data.resize(extra_data_size);
return std::make_shared<BufferString>(std::move(extra_data));
#else
WarnL << "请开启MP4相关功能并使能\"ENABLE_MP4\",否则对H265的支持不完善";
return nullptr;
@@ -680,4 +821,3 @@ CodecPlugin h265_plugin = { getCodec,
getFrameFromPtr };
}//namespace mediakit